{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-2477","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-05-02T12:07:02.319Z","datePublished":"2023-05-02T14:00:06.199Z","dateUpdated":"2024-08-02T06:26:08.914Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-10-23T05:18:41.036Z"},"title":"Funadmin Cx.php tagLoad cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"CWE-79 Cross Site Scripting"}]}],"affected":[{"vendor":"n/a","product":"Funadmin","versions":[{"version":"3.2.0","status":"affected"},{"version":"3.2.1","status":"affected"},{"version":"3.2.2","status":"affected"},{"version":"3.2.3","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability."},{"lang":"de","value":"In Funadmin bis 3.2.3 wurde eine problematische Schwachstelle ausgemacht. Hierbei betrifft es die Funktion tagLoad der Datei Cx.php. Durch Manipulation des Arguments file mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}}],"timeline":[{"time":"2023-05-02T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-05-02T00:00:00.000Z","lang":"en","value":"CVE reserved"},{"time":"2023-05-02T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-05-24T18:58:44.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"VulDB Gitee Analyzer","type":"tool"}],"references":[{"url":"https://vuldb.com/?id.227869","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.227869","tags":["signature","permissions-required"]},{"url":"https://gitee.com/funadmin/funadmin/issues/I6W2YL","tags":["exploit","issue-tracking"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T06:26:08.914Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.227869","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.227869","tags":["signature","permissions-required","x_transferred"]},{"url":"https://gitee.com/funadmin/funadmin/issues/I6W2YL","tags":["exploit","issue-tracking","x_transferred"]}]}]}}